APP-03.2: Security testing in the pipelines should include SAST (static analysis) and SCA, which are the two primary categories of tooling to detect application-level security defects. At least some pipelines should use these tests, but for Level 3, this does not need to be consistent or standardized yet.
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none